CAS-004 Governance, Risk, and Compliance Practice Question
A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)
⚠ Common exam trap
CAS-005 often tests the difference between intrinsic vulnerability severity (CVSS) and contextual risk factors (asset criticality, exploit availability), so candidates must not treat patch availability or age as core risk determinants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Availability of a public exploit
Option A (Availability of a public exploit) is correct because a publicly available exploit, especially one weaponized in frameworks like Metasploit or CISA's KEV catalog, dramatically increases the likelihood of active exploitation and thus raises the risk level. Option C (Asset value or criticality) is correct because the same vulnerability poses far greater risk on a high-value asset such as a domain controller or PII database than on an isolated test machine, directly affecting impact. Option D (CVSS base score) is correct because it provides a standardized, vendor-agnostic metric of intrinsic severity based on exploitability and impact, forming a foundational input to risk prioritization. Option B (Vendor patch availability) is not one of the three because a patch being available reduces exposure but does not itself define the inherent risk level of the vulnerability. Option E (Number of days since discovery) is not selected because age alone is a weak indicator; a long-unpatched critical flaw may be high risk, but time since discovery is not a standard risk-scoring factor like exploit availability, asset criticality, or CVSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Availability of a public exploit
Why this is correct
A publicly available exploit raises the likelihood of active attacks, since attackers can readily obtain working code. This directly increases the vulnerability's risk level when prioritising remediation, alongside impact factors such as asset criticality and exposure.
- ✗
Vendor patch availability
Why it's wrong here
Patch availability affects how quickly a flaw can be fixed, not the inherent risk of exploitation. It is tempting because unpatched software is exploitable, but risk scoring weighs likelihood and impact — CVSS exploitability, exposure, data sensitivity — not remediation logistics.
- ✓
Asset value or criticality
Why this is correct
Asset value or criticality determines the potential business impact if a vulnerability is exploited, since compromise of a high-value system causes greater harm. This impact dimension, combined with likelihood factors, drives the overall risk rating used to prioritise remediation.
- ✓
CVSS base score
Why this is correct
The CVSS base score quantifies the intrinsic severity of a vulnerability using exploitability and impact metrics, giving the analyst a standardised, vendor-neutral severity rating. It satisfies the need to rank remediation effort objectively, though environmental and threat context must still temper the final risk level.
- ✗
Number of days since the vulnerability was discovered
Why it's wrong here
Elapsed time since discovery says nothing about exploitability or business impact; an old, unexploitable bug stays low risk. Age is tempting as a proxy for exposure, but risk ranking uses CVSS base metrics, active exploitation evidence, and asset criticality instead.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.